F-Secure on a new nasty

(0 votes, average: 0.00 out of 5)You need to be a registered member to rate this post.

Something to watch out for: From F-Secure:

Somebody has lately been seeding emails like the one pictured below.

Obviously, they are not from Symantec. And when you click the link, you end up getting redirected to a web page which will initiate an autodownload of a file called “rxBot.exe”, which is – you guessed it – a variant of the RXBot family.

A mail like this will pass most corporate email filters. There’s no attachment. There’s no masked link either, so phishing filters probably won’t detect it.